Cross-Site Request Forgery?

I received a security report from a third party security scanner and the report said that a site that I built was vulnerable to cross-site request forgery. The report results:

Threat
The page can be easily framed. Anti-framing measures are not used.

Impact
Clickjacking and Cross-Site Request Forgery (CSRF) can be performed by framing the target site. An attack can trick the user into clicking on the link by framing
the original page and showing a layer on top of it with dummy buttons.

Solution
Two of the most popular prevention are: X-Frame-Options: This header works with modern browsers and can be used to prevent framing of the page. Note that is must be an HTTP header, the setting is ignored if it is created as an “http-equiv” meta element within the page. Framekiller: JavaScript code that prevents the malicious user from framing the page.

Are these solutions possible within the X-theme?

Thank you

Hi there,

Thanks for posting in.

It’s not theme related, you should contact your hosting provider and configure it for you. In fact, this should be done by your security plugin if available or by your site’s security. You can manually do it by adding PHP code to send header information, but it’s more efficient to configure it on your server instead of scripting level.

Thanks.

Thank you.

Thank you for your understanding.